Skip to content

SIDE QUESTSecurity Leadership

Lie to Know the Truth

Most detection waits for an attacker to trip over something real. Defensive deception puts something there on purpose, so the only people who touch it are the people who should not.

Samantha Swift / BOOTx /

ORIGINAL SOURCE

WATCH / BOOTx

A talk about defensive deception using honeypots, honey files, and honey credentials to detect adversary activity and learn more about attackers operating within an environment.

WATCH THE ORIGINAL (opens on an external site)

Originally published by BOOTx. Cyber Increment did not host or publish this source.

WHY WE'RE SHARING IT

Lie to Know the Truth is a talk about defensive deception: deliberately placing things inside an environment that have no legitimate reason to be used, so that any interaction with them is a signal.

What it gets into

  • Honeypots, and what they tell defenders that ordinary monitoring does not.
  • Honey files, and using content nobody should open as a detection trigger.
  • Honey credentials, and what happens when an account that is never used is suddenly used.
  • Detecting adversary activity inside an environment rather than only at its edge.
  • Learning more about attackers who are already operating within an environment.

The talk is from 2017, and the underlying idea has aged well: detection improves when defenders decide in advance what a false step looks like.

RELATED INSIGHTS

CONTINUE?

Want to talk it through?

If any of this is live in your business right now, a short conversation is usually the fastest way to work out what to do next.